Skip to content

LazyTitan33/WooCommerce-SQLi

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 

Repository files navigation

CVE-2021-32790

This is a Proof of Concept for the WooCommerce 3.3-5.5 Blind Time based SQL Injection written quickly in python3.

In my case it was Unauthenticated but if yours require authentication, make sure to add the cookies in the script and it should still work. When adding the URL as an argument, you will see the response time. Default script has a sleep of 5 seconds. Feel free to adjust as needed.

image

image

For the inspiration, special thanks go to @zeroauth who wrote the sqlmap tamper script below.

https://zeroauth.ltd/blog/2021/07/16/proof-of-concept-exploit-for-woocommerce-3-3-5-5-sql-injection-with-sqlmap-tamper/

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages